You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I would like to bring to your attention a security vulnerability in the djangorestframework-simplejwt package, specifically version 5.4.0. The vulnerability (CVE-2024-22513) has been identified as an information disclosure issue caused by missing user validation checks in the for_user method.
Affected versions of the package allow a user to access web application resources even after their account has been disabled, posing a significant security risk.
Hello maintainers,
I would like to bring to your attention a security vulnerability in the djangorestframework-simplejwt package, specifically version 5.4.0. The vulnerability (CVE-2024-22513) has been identified as an information disclosure issue caused by missing user validation checks in the for_user method.
Affected versions of the package allow a user to access web application resources even after their account has been disabled, posing a significant security risk.
References:
https://data.safetycli.com/v/66963/f17/
The text was updated successfully, but these errors were encountered: